Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-7455

Опубликовано: 07 мая 2016
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

Комментарий

CWE-415: Double Free

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:littlecms:little_cms_color_engine:2.0:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.1:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.2:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.3:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.4:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.5:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.15231
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 10 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

redhat
почти 10 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

CVSS3: 9.8
debian
почти 10 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvr ...

CVSS3: 9.8
github
больше 3 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

EPSS

Процентиль: 94%
0.15231
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-Other